CVE-2024-39937

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jul 4, 2024
Updated: Jul 9, 2024
CWE ID 22

Summary

CVE-2024-39937 is a newly disclosed vulnerability affecting supOS 5.0. This issue permits attackers to perform directory traversal attacks through the api/image/download endpoint, enabling them to read sensitive files outside of the intended directory. By manipulating the fileName parameter, an adversary can access files that are located above the current working directory, posing a significant risk to system security. The vulnerability could potentially lead to data leakage or unauthorized access, underscoring the importance of applying available patches promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • supOS

Affected Vendors

  • Zhejiang Lanzhuo Industrial Internet Information Technology Co Ltd